Avatar for Figment
Figment
Actively Hiring
Stake & Build Web3
  • Top 10% of responders
    Figment is in the top 10% of companies in terms of response time to applications
  • Responds within two weeks
    Based on past data, Figment usually responds to incoming applications within two weeks
  • B2B
  • +2

Senior Red Team Operator

  • $150k – $180k
  • Full Time
Posted: 2 weeks ago• Recruiter recently active
Visa Sponsorship

Not Available

Hires remotely in
RelocationAllowed
Hiring contact

Bill Mehleisen

About the job

About the Role

As a senior member of the Figment Security Red Team, your responsibility will be to design and execute campaign-based security testing for Figment. This will involve targeting multiple types of assets. Successful applicants should have the ability to evaluate environments, applications, systems, or processes to identify vulnerabilities. Furthermore, they should be able to translate these findings into practical attack strategies for real-world scenarios.

To effectively support Figment's security initiatives, you will need to utilize your knowledge of cloud platforms, CI/CD pipelines, operating system security, networking and protocols, firewalls, databases, middleware applications, and scripting. You will also need to effectively communicate highly technical information to internal customers. Additionally, you will be responsible for providing remediation recommendations and validating security remediation findings.

Responsibilities

  • Document processes, procedures, and workflows for red team operations.
  • Perform a full range of red team activities including network intrusion, cloud and development pipeline exploitation, web and application testing, source code reviews, threat analysis, and detection evasion techniques.
  • Develop comprehensive and accurate reports and presentations for both technical and executive audiences.
  • Collaborate with seniors in the security team to enhance the red team strategy and improve the company's security posture.
  • Effectively communicate findings and strategies to stakeholders, including technical staff, executive leadership, and legal counsel.
  • Provide practical and risk-appropriate recommendations to address vulnerabilities.
  • Configure and safely use attacker tools, tactics, and procedures in Figment environments.
  • Enhance Figment's red teaming processes by developing and improving scripts, infrastructure, tools, and methodologies.
  • Offer recommendations and guidance to enhance the defensive capabilities of the team and its ability to defend the Figment Enterprise.
  • Provide mentoring and training to blue team members and actively participate in cross-team security exercises.
  • Provide technical expertise and support during incident response and assist in creating post-incident action plans.

Qualifications

You’ll need to have:

  • Bachelor's degree or four or more years of work experience
  • Experience in cloud-based exploitation or security assessments
  • Experience in network penetration testing and manipulation of network infrastructure.
  • Experience in API and web application assessments.
  • Experience in scripting and automation of simple tasks using Bash, Python, or similar
  • Experience developing, extending, or modifying exploits, shellcode or exploit tools.
  • Experience with container orchestration management tools such as Docker and Kubernetes.
  • Experience with source code review for control flow and security flaws.
  • Experience with red, blue, or purple teaming exercises.
  • Strong knowledge of offensive security and pentesting tooling such as Kali Linux, Burp Suite, Mythic C2, and other open source tools.
  • Strong technical writing.

Even better if you have:

  • Industry certifications such as OSCP/OSCE, OSEP, OSWE, GPEN, GCPN, GWAPT, or GXPN.
  • Solid understanding and experience working with Github and Github deployment pipelines
  • Solid understanding of public cloud environments including AWS, Azure and Google.
  • Solid understanding of OWASP Top 10 and how to effectively exploit them.
  • Thorough understanding of network protocols, data on the wire, and covert channels.
  • Programming skills as well as the ability to read and assess applications written in multiple languages such as Go, Rust, and Ruby.
  • Understanding of security risks for blockchain and crypto.
  • Familiarity with Solidity, Vyper, Yul, Cairo, Rust, or Move.

One of Figment’s core principles is “Making the Invisible Visible” - ensuring transparency and information sharing in all communication. Figment is committed to transparency regarding pay, benefits, and other compensation types for all internal roles as well as all roles being hired for.

Base Salary: The CAD base salary range for this position is CAD $150,000 - $180,000. The US base salary range for this position is USD $150,000 - $180,000. This range reflects base salary only, and does not include additional compensation or benefits. For candidates in other countries, the pay range will be disclosed upon your first interview with Figment (being a globally remote company, the list of salary ranges would simply be too long to note here!). The range displayed reflects the minimum and maximum range for a new hire across all Canada or the US. A candidate’s specific pay within the range will be determined by various factors including job-related skills, relevant education, and training.

Benefits: All employees of Figment receive the following competitive benefits. For candidates beyond Canada and the US, benefits will be outlined during your first interview with Figment.

  • 100% remote-first environment, with co-working spaces in our employee “hubs” across the globe for those who enjoy a hybrid model
  • 4 weeks of PTO that kick in day one, with an additional 1 week of flex days
  • Extended company-paid health benefits that kick in day one
  • Best in class parental leave and flexible arrangements
  • A home office stipend to create a space that you enjoy working in
  • Monthly Wifi reimbursement
  • A yearly Learning & Development budget
  • 401K (US) or RRSP match (Canada)
  • Stock Options in the company
  • Competitive bonus (based on company performance) that is distributed bi-annually - we believe that the company’s success should be shared with our employees often
    • For roles listed within the Sales Department, there is instead a competitive commissions structure which will be outlined during your first interview with Figment
  • Annual onsite company gatherings and retreats to inspire team bonding, collaboration, and fun!
  • A culture of honesty, professionalism and risk taking in a high-growth environment

See here for Figment's Privacy Policy and California Employee Privacy Policy.

At Figment, we have a thorough hiring process to verify the identity of all job candidates. This includes checking documents, conducting in-person interviews, biometric authentication and completing background checks. Candidates must pass all these steps to be considered for a job with Figment. Anyone who provides false information or tries to skip these steps will be disqualified from the hiring process immediately.

About the company

Figment company logo

Figment

Actively Hiring
Stake & Build Web3201-500 Employees
  • Top 10% of responders
    Figment is in the top 10% of companies in terms of response time to applications
  • Responds within two weeks
    Based on past data, Figment usually responds to incoming applications within two weeks
  • B2B
  • Scale Stage
    Rapidly increasing operations
  • Valuation $1B+
    This company has a valuation of $1B or more
Learn more about Figment image

Funding

AMOUNT RAISED
$52M
FUNDED OVER
3 rounds
Rounds
C
Undisclosed amount
Series C - Dec 2021+2

Perks

Health & Wellness
Company-paid medical/vision/dental for employees and family
Family-Friendly Benefits
Best in class parental leave and flexible arrangements
Compensation
Comprehensive packages including competitive salary, bonus and equity
Remote First + Hybrid Working Environment
Fully remote-first teams with regular team retreats to foster team bonding
Work/Life Flexibility
Remote work with a flexible PTO policy - 20 days PTO plus 5 flexible days

Founders

Matt Harrop
Founder • 3 years
Waterloo
image
Lorien Gabel
Founder • 3 years
Jackson
image
Andrew Cronk
Founder • 3 years
Lansing
image
View the team image

Similar Jobs

Pulse company logo
Pulse
Transforming healthcare by creating remarkable experiences for doctors and patients
Hack For Change company logo
Hack For Change
Technology Interventions For Social Good
Bobble AI Technologies company logo
Bobble AI Technologies
World's first Conversation Media Platform, enriching everyday conversations!
Kennect Technologies company logo
Kennect Technologies
Kennect is a SaaS Company, leading the way in Sales Performance Management
ATLAS ANALYTICS company logo
ATLAS ANALYTICS
Your Sales Team, Reimagined. Tailored & Customized Video Outreach Campaigns